Privacy Policy
Effective date: 21 May 2026
This policy describes how SYNTEX APPS ("we", "us") collects and uses personal information when you use My Taxi Base (the "Platform") — including the dispatch dashboard, APIs, and per-tenant online booking pages.
1. Who this policy applies to
- Tenant users — staff of taxi and private-hire businesses (admins, dispatchers, viewers) who log into the dashboard.
- End customers — people who register or book on a tenant's public booking page (e.g.
/book/[company]). - Drivers and personal assistants — where their details are managed in the Platform (including driver-app accounts and optional Telegram linkage for personal assistants / ops where used).
- Website visitors — e.g. marketing pages, demo requests, and support contact.
2. Controller and processor roles
Data protection law distinguishes the organisation that decides why data is used (controller) from one that processes it on their instructions (processor).
- For tenant business data (bookings, jobs, end-customer accounts created on that tenant's booking page, driver records, messages, and operational exports), the tenant is generally the controller and we act as a processor, providing hosting and software on their instructions.
- For Platform account data (tenant staff logins, platform balance top-ups and plan billing to us, security logs, abuse prevention, and product communications from SYNTEX APPS), we act as a controller.
If you are an end customer booking with a taxi company, that company is primarily responsible for your booking data. Contact them first for access or deletion requests relating to your trips. We will assist tenants where our processing agreement requires.
3. Information we collect
3.1 Tenant dashboard users
- Identity and contact (name, email, role, tenant affiliation)
- Credentials and authentication data (password hashes, session tokens, optional 2FA)
- Legal acceptance records (terms/privacy version and timestamp)
- Usage and audit logs (actions in the dashboard, IP address, device/browser signals)
3.2 End customers (online booking)
- Account details (name, email, phone, password hash)
- Booking details (pick-up, drop-off, stops, schedule, fare quotes, special requirements)
- Payment status and Stripe identifiers when the tenant enables card payments (we do not store full card numbers)
- Promo code usage and trip history visible in the customer account area
3.3 Operations data
- Jobs, routes, assignments, statuses, pricing, invoices, and wallet/settlement records
- Driver and PA profiles, documents, driver-app accounts, and optional Telegram linkage where used
- In-app messages (and Telegram where used for personal assistants / ops)
- Support conversations with SYNTEX APPS (in-dashboard support)
3.4 Technical data
- Logs, cookies, and similar technologies (see section 8)
- Address search and routing metadata when completing bookings (via third-party geocoding/routing providers configured for the service)
- Uploaded files (e.g. logos, documents) stored on our object storage
4. How we use information
- Provide, operate, and secure the Platform (authentication, dispatch, booking, reporting)
- Process tenant platform balance top-ups and plan fees and, where enabled, facilitate ride payments through Stripe Connect to the tenant's connected account
- Send service-related emails (e.g. booking confirmations, password reset, verification) when triggered by tenant or end-customer actions
- Provide customer support and improve reliability
- Detect fraud, abuse, and security incidents
- Comply with law and enforce our terms
We do not operate a marketing email service for tenants. Tenants may export their own end-customer lists for their business records; any promotional email they send using other tools is their responsibility, not ours.
5. Legal bases (UK GDPR)
Where we are controller, we rely on appropriate bases including:
- Contract — to provide the Platform and related support you signed up for
- Legitimate interests — security, product improvement, and proportionate business administration, balanced against your rights
- Legal obligation — where we must retain or disclose data by law
- Consent — where required (e.g. non-essential cookies if presented)
Where we process tenant business data as processor, the tenant determines the lawful basis and provides appropriate privacy information to their drivers and end customers.
6. Sharing and subprocessors
We do not sell personal information. We share data only as needed to run the service, including with:
- Hosting and infrastructure providers
- Stripe (platform balance top-ups / plan billing and, where enabled, Stripe Connect ride payments)
- Email delivery providers for transactional messages
- Telegram (when tenants enable optional Telegram for personal assistants / ops messaging)
- Geocoding, maps, or routing providers for address and distance features
- Security and abuse-prevention services (e.g. bot protection on public forms)
We may also disclose information if required by law, to protect rights and safety, or in connection with a merger or asset sale with appropriate safeguards.
7. International transfers
Data may be processed in the United Kingdom and other countries where our providers operate. Where required, we use appropriate safeguards (such as UK international data transfer mechanisms) for transfers outside the UK.
8. Cookies and similar technologies
The dashboard and booking pages use cookies and similar storage for essential functions, including keeping you signed in (HttpOnly session cookies), security, and remembering preferences. Payment pages may set cookies required by Stripe. We may use analytics or security cookies on public marketing pages where configured.
9. Retention
We keep information only as long as needed for operations, legal compliance, accounting, dispute resolution, and security. Retention varies by data type, tenant settings (e.g. recycle bin / archived records), and contractual requirements. Tenants should define their own retention practices for end-customer relationships.
10. Security
We apply administrative, technical, and organisational measures designed to protect data against unauthorised access, loss, or misuse, including access controls, encryption in transit, tenant isolation, and monitoring. No system is completely risk-free.
11. Your rights
Under UK data protection law you may have rights to access, rectify, erase, restrict, object, and port personal data, and to withdraw consent where processing is consent-based. You may also complain to the UK Information Commissioner's Office (ICO).
Tenant users: contact syntexapps@gmail.com.
End customers: contact the taxi company you booked with first; they control your booking relationship. You may contact us if you need help reaching the correct tenant.
12. Children
The Platform is a business service. Online booking accounts are not directed at children. Tenants must not use the service to unlawfully process children's data without proper authority and safeguards.
13. Changes to this policy
We may update this policy from time to time. The effective date at the top will change when we do. Material changes may be communicated in the product or by email where appropriate. Continued use after the effective date constitutes notice of the update where permitted by law.
14. Contact
SYNTEX APPS — privacy enquiries: syntexapps@gmail.com